Document Numbering System Policy

Document Management
Compliance
Defines the document numbering system used for Tessera policy, procedure and reference documents.
Title Document Numbering System Policy
Doc# POL-COMP-025
Version 1.0
Date 26-11-2023
Owner Head of Compliance (M. Dubois)
Approved By CISO (I. Ferreira)
ISO/IEC 27001:2022 A.5.1 — Policies for information security

Introduction

The document numbering system gives every Tessera policy, procedure and reference document a unique, structured identifier so that documents can be identified, categorised, retrieved and cross-referenced consistently across teams.

Policy Statements

  1. System design. The numbering system is a hybrid of category-specific prefixes and sequential numbering, reflecting the nature of the document.
  2. Abbreviation usage. Each document carries a category abbreviation from the “Category Abbreviations” table below.
  3. Sequential numbering. A sequential number, starting at 001 within each category, follows the category prefix to keep identifiers unique.
  4. Version control. Every document carries a version number and date in its header so amendments can be tracked.

Controls and Procedures

  1. Assigning document numbers.
    • On creation, the Document Control Officer assigns a number of the form ABB-XXX, where ABB is the category abbreviation and XXX is the sequential number.
    • Example: the first policy in the Data category is POL-DATA-001.
  2. Category abbreviations.
    • The Document Control Officer maintains the list below; it is published for reference across all teams.
Abbreviation Category Description
ACCE Access Control
ASSE Asset Inventory
AUDI Audit Management
AUTH Authentication and Authorization
BACK Backup and Recovery
CHAN Change Management
COMM Communication
COMP Compliance
DATA Data (classification, lifecycle, protection, security)
DEVI Device Security
DISA Disaster Recovery
DOCU Document Management
EDUC Education
EMPL Employee Management
ENCR Encryption Standards
EXTE External Communication
FACI Facility Management
FINA Financial
HUMA Human Resources
INCI Incident Response
ITIN IT Infrastructure
ITMA IT Management
NETW Network Management
OPER Operational Continuity / Security
ORGA Organisational Structure
PHYS Physical Security
POLI Policy Development
PRIV Privacy
PROC Procurement
REGU Regulatory Compliance
RISK Risk Assessment / Management
SECU Security (architecture, awareness, management, secure development)
SECU Security Awareness
SKIL Skills Development
SOFT Software
THRE Threat Intelligence
TRAI Training
USER User Consent
VEND Vendor Management
VERS Version Control
WEBT Web Technologies

[M. Dubois: the legacy “HEAL” (Healthcare Compliance) category was removed in the 2025 cleanup — Tessera is not a healthcare-covered entity. Two historical documents still carry HEAL prefixes and will be renumbered under COMP at their next review. If you need a healthcare-specific control, scope it under COMP and tie it to the relevant tenant schedule, not a separate category.]

[Reviewer note: there is a duplicate SECU row above (Security / Security Awareness) — known drift from the 2024 consolidation. Flagged for cleanup at the next version bump; do not re-issue either number in the meantime.]

  1. Document-type prefixes.
    • The Document Control Officer maintains the document-type prefixes below.
    Abbreviation Type Description
    POL Policy
    SOP Standard Operating Procedure
    ISMS-PR ISMS procedure (e.g. ISMS-PR-014, joiner-mover-leaver)
    DOC Other document (reference, register, plan)
  2. Document updates and version control.
    • Any update requires a new version number and date, recorded in the policy document log maintained by the Document Control Officer.
    • Revisions reflect changes in content or scope; each version is archived for future reference.
  3. Compliance and monitoring.
    • The numbering system is audited regularly to ensure adherence to internal standards and that it remains effective.
    • Non-compliance or inconsistencies in document numbering are corrected promptly to prevent documentation errors.